Get a free website with any plan

See how
WORDPRESS

Scanning WordPress for malware

Last updated

IN SHORT

Flashcloud servers run Imunify360 to block known threats at the server level, but application-level cleanups require checking WordPress directly. Inspect your administrator users, reinstall fresh core files through your dashboard, or run a full scan using Wordfence or Sucuri Security. Replacing infected plugin and theme files with fresh copies ensures the cleanest result.

If your WordPress site is showing unfamiliar admin users, redirecting visitors to spam sites, or flagged by Google Safe Browsing, start with a scan, not a full reinstall. Flashcloud runs Imunify360 at the server level on every hosting account, which already screens for known malware signatures and blocks a lot of attacks before they land. What's left to check is application-level: your WordPress files, database, and plugins for anything that slipped through or was planted via a compromised plugin or weak password.

Work through the checks below in order. Most infections show up in the first two steps without needing a dedicated scanner plugin.

Check the obvious signs first

Before installing anything, look for the common tells:

  • Unfamiliar admin users. Open wp-admin → Users and check every account with Administrator role. Malware often creates a hidden admin account as a backdoor.
  • Unexpected plugins or themes. Check wp-admin → Plugins and wp-admin → Appearance → Themes for anything you didn't install. Attackers sometimes drop a disguised plugin with a generic name like "WP Cache Helper."
  • Modified core files. Go to wp-admin → Dashboard → Updates and click "Re-install Now" next to your current WordPress version. This overwrites core files with clean copies without touching your content, and it's the fastest way to rule out core file tampering.
  • Search engine or browser warnings. Search site:yourdomain.com in Google, or check wp-admin → Tools → Site Health for security-related flags. See WordPress Site Health warnings and which ones matter for which warnings are worth chasing.

Back up before you touch anything

Take a fresh backup before you start removing files or plugins, even though the site is already compromised. You want a point-in-time copy in case a cleanup step goes wrong, and you want the infected copy preserved in case you need to compare file timestamps later. Automatic backups run on most hosting accounts, so you likely have a recent restore point to fall back on if things get worse.

Use a malware scanner plugin when you need to go deeper

If the manual checks above don't turn up anything obvious but you still suspect an infection, a dedicated scanner plugin checks file integrity against known-good WordPress core, theme, and plugin signatures, and flags suspicious code patterns manual review would miss.

  1. Install a reputable scanner (Wordfence and Sucuri Security are the two most widely used) from wp-admin → Plugins → Add New.
  2. Run a full scan, not a quick scan. Full scans check file contents against the original plugin and theme repositories, not just file existence.
  3. Review every flagged file individually before deleting. Scanners flag modified core files, but also flag legitimate customizations, like a child theme's functions.php, as a false positive. Don't mass-delete without checking.
  4. For infected files inside WordPress core, theme, or plugin folders, replace them by reinstalling that specific plugin or theme fresh rather than trying to hand-edit out the malicious code. It's faster and you know the result is clean.
  5. For files that don't belong to any known plugin or theme (random PHP files in wp-content/uploads, for example), delete them directly through the File Manager tile on your service page in the portal, or via File Manager in cPanel.

Close the door it came in through

Scanning and cleaning fixes the symptom. If you don't close the entry point, it comes back. The most common causes:

  • Outdated plugins or themes. Old versions with known vulnerabilities are the number one infection vector. Update everything, and remove plugins and themes you're not actively using instead of leaving them installed and inactive.
  • Weak admin passwords. Reset every administrator password after a cleanup, not just the one you think was compromised.
  • Nulled or pirated plugins/themes. Free copies of premium plugins from non-official sources are a common way malware gets installed intentionally. Replace them with licensed originals.

Once you're confident the site is clean, test everything on a copy before you consider the job finished on a busy or revenue-generating site. See Using WordPress staging to verify plugin and theme updates don't break anything, especially if you're running a WooCommerce store where a broken checkout after cleanup costs real sales.

When to contact support

If you've run a full scanner scan and still see reinfection within a day or two, or if the site is completely inaccessible and you can't get into wp-admin at all, open a ticket from Support → New ticket in the portal. Persistent reinfection usually means something wasn't fully removed, like a scheduled task or a backdoor file outside the normal plugin/theme folders, and that's worth a second set of eyes from a real person rather than repeated scan-and-delete cycles.

Common questions

Does Flashcloud scan my WordPress site automatically?

Yes. Flashcloud runs Imunify360 on every hosting account to screen for known malware signatures and block attacks before they land. It does not replace checking WordPress internally for weak passwords, outdated plugins, or unauthorized admin users.

Will reinstalling WordPress core delete my content?

No. Clicking Re-install Now in wp-admin overwrites your core files with clean copies without touching your site content. It is the fastest way to remove core file modifications.

Why does malware keep coming back after cleanup?

The original entry point is still open. Reinfection usually happens because of outdated plugins, weak administrator passwords, nulled themes, or hidden backdoors placed outside normal theme and plugin folders.

When should I contact support about an infection?

Open a ticket if your site reinfects within a day or two, or if you are locked out of wp-admin completely. Persistent issues often mean a backdoor or scheduled task was missed and requires manual inspection.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.